Back to search
CVE-2017-14087
Published: Oct 5, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
| Vendor | Product | Versions |
|---|---|---|
Trend Micro | Trend Micro OfficeScan | affected XG (12.0) |
References
https://success.trendmicro.com/solution/1118372
x_refsource_CONFIRM
20170928 CVE-2017-14087 Trend Micro OfficeScan v11.0 and XG (12.0)* Host Header Injection (apparitionsec / hyp3rlinx)
mailing-list
x_refsource_BUGTRAQ
101074
vdb-entry
x_refsource_BID
20170929 Trend Micro OfficeScan v11.0 and XG (12.0)* Host Header Injection CVE-2017-14087
mailing-list
x_refsource_FULLDISC
1039500
vdb-entry
x_refsource_SECTRACK
42895
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now